| FMRS | 69 / 100 · C | 77 / 100 · B | 75 / 100 · B |
| Reliability | 10 / 20 | 12 / 20 | 13 / 20 |
|---|
| Security and permissions | 14 / 20 | 16 / 20 | 12 / 20 |
|---|
| Maintenance | 13 / 20 | 16 / 20 | 16 / 20 |
|---|
| Documentation | 17 / 20 | 18 / 20 | 17 / 20 |
|---|
| Setup experience | 15 / 20 | 15 / 20 | 17 / 20 |
| Best for | - Teams that need AI access to one or more MediaWiki wikis.
- Users combining wiki retrieval with controlled content maintenance.
- Users of Claude, Codex, VS Code, Cursor, or other listed MCP clients.
| - Hevy PRO users who want AI assistants to directly access their workout data
- People who prefer using MCP clients like Claude, Cursor, Codex for fitness tracking
- Anyone needing summaries and insights from their training data
| - Scenarios needing clean, structured web context fed to an AI assistant
- Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
|
| Not for | - Knowledge bases or content systems that do not use MediaWiki.
- Workflows requiring writes without configuration or permissions.
- Users expecting client or protocol compatibility that is not evidenced by the source.
| - Users without a Hevy PRO subscription (API key required)
- Users who want to use the server without an API key
- Those needing delete workflows (Hevy API does not expose delete endpoints)
| - Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
- Sites that explicitly disallow automated access (robots.txt)
|
| Required permissions | - Read operations depend on the wiki being public or configured and reachable.
- Write tools require the corresponding MediaWiki permissions; write tools are hidden from tools/list when the default wiki is read-only.
- File uploads require allowed upload directories to be configured.
- Cargo queries may require the runcargoqueries user right.
- Private wikis and authenticated operations require OAuth, tokens, bot passwords, or another configured authentication method.
| - Requires HEVY_API_KEY environment variable for Hevy API authentication
- Can create, update, and replace workouts, routines, folders, templates, and body measurements via tools
- Read operations can fetch workouts, routines, folders, templates, history, and user info
| - Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
- firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
|
| Risks and side effects | - In HTTP mode, Authorization Bearer tokens are forwarded to MediaWiki; authentication should be handled by a reverse proxy with TLS termination outside an untrusted network.
- Before exposing HTTP to others, configure allowed hosts and origins to reduce DNS-rebinding and cross-origin risks.
- Write, delete, move, and upload tools can change wiki content or files; use least-privilege credentials.
- Outbound URL fetching and uploads are subject to SSRF and size limits; internal destinations require MCP_TRUSTED_HOSTS.
- Tool responses have content, file-data, request-body, and upload size caps.
| - API key can be misused if leaked; do not expose in URLs, logs, or screenshots
- Create operations may produce duplicates on retry; update operations replace existing records
- The server sends data to the Hevy API and may send telemetry to external services unless disabled
| - Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
- firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
|
| Supported clients | Claude Code, Codex, Claude Desktop, VS Code, Cursor, Antigravity, OpenCode, Devin Desktop, Zed, LM Studio | Claude Desktop, Cursor, Codex, Google Antigravity | Claude Desktop, VS Code, Cursor, Windsurf, Zed, Amp |
| Tools | 46 | 26 | 11 |